fix: Qiniu下载改用HTTPS签名URL,http→https

This commit is contained in:
mediabot-pt
2026-07-01 18:18:56 +08:00
parent a4a11fb503
commit db2a05ee4b

View File

@@ -87,19 +87,14 @@ public class QiniuStorageService implements StorageService {
log.warn("Qiniu stat 失败 {}: {}", path, e.response != null ? e.response.error : e.getMessage());
}
// 直接 HTTP 拉取(公开桶),不用签名
String rawUrl = "http://" + downloadDomain + "/" + path;
// 用 HTTPS 签名 URL 拉取
String baseUrl = "https://" + downloadDomain + "/" + path;
String signedUrl = auth.privateDownloadUrl(baseUrl, 3600);
try {
var req = HttpRequest.newBuilder().uri(URI.create(rawUrl))
var req = HttpRequest.newBuilder().uri(URI.create(signedUrl))
.timeout(Duration.ofSeconds(10)).GET().build();
var resp = httpClient.send(req, HttpResponse.BodyHandlers.ofString());
if (resp.statusCode() == 200) return resp.body();
// 公开桶失败,尝试签名URL
String signedUrl = auth.privateDownloadUrl(rawUrl, 3600);
req = HttpRequest.newBuilder().uri(URI.create(signedUrl))
.timeout(Duration.ofSeconds(10)).GET().build();
resp = httpClient.send(req, HttpResponse.BodyHandlers.ofString());
if (resp.statusCode() == 200) return resp.body();
log.warn("Qiniu 下载失败 {}: HTTP {}", path, resp.statusCode());
} catch (Exception e) {
log.warn("Qiniu 下载失败 {}: {}", path, e.getMessage());